×

Systems and methods for computer worm defense

  • US 8,516,593 B2
  • Filed: 10/12/2012
  • Issued: 08/20/2013
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A computer worm defense system comprising:

  • a plurality of computer worm containment systems, each computer worm containment system comprisinga worm sensor implemented in a computing device and configured to generate a computer worm identifier for a computer worm propagating within a communication network, the worm sensor comprisingan alternate computer network, communications traffic being monitored on a communication network and filtered from the communication network for analysis by the alternate computer network, the filtered communications traffic having one or more suspicious characteristics of a computer worm, wherein the one or more suspicious characteristics indicating that the filtered communication traffic should be analyzed to determine whether or not the filtered communications traffic comprises a computer worm; and

    a controller configured to monitor the alternate computer network, and to determine whether the filtered communications traffic comprises a computer worm by analysis of the filtered communications traffic, the controller being operable tomonitor a replay of transmission of the filtered communications traffic within the alternate computer network, andwhen the filtered communications traffic is determined to comprise a computer worm, generate the computer worm identifier for the computer worm based on anomalous behavior caused within the alternate computer network during replay of transmission of the filtered communications traffic by the computer worm.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×